Impact
The Linux kernel contains a design flaw in its Bluetooth ISO socket handling logic. When an ISO socket is closed, the reference to the socket object may not be released correctly, causing a stale reference to accumulate as sockets are repeatedly created and destroyed. While the description does not indicate an immediate denial‑of‑service, a steady leak could exhaust kernel memory or leave orphaned socket descriptors, potentially destabilizing the system.
Affected Systems
The defect resides in the core Linux kernel image, specifically within the Bluetooth ISO implementation. All kernel packages that include the affected source code are potentially impacted. Because the CPE indicates a kernel‑wide scope and no specific version range is listed, any kernel built with the default Bluetooth ISO stack should be considered vulnerable until the upstream changes are incorporated.
Risk and Exploitability
Based on the description, it is inferred that the attack vector requires a local user with permission to create Bluetooth ISO sockets. The flaw can be exercised by any such process. The CVSS score of 5.5 reflects a moderate impact. The EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to repeatedly open and close ISO connections to manifest a memory leak, which is more likely to degrade system stability than directly compromise confidentiality or integrity. Thus, the overall risk is low to moderate.
OpenCVE Enrichment
Debian DSA